PT-2026-44936 · Dokploy · Dokploy
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dokploy versions prior to 0.26.8
Description
Dokploy is a self-hostable Platform as a Service (PaaS) where the schedule router fails to enforce organization or role checks. This allows any authenticated user to create, update, run, or delete schedules belonging to other organizations by providing the
scheduleId or serverId. Because schedule types server and dokploy-server write and execute scripts on the host or remote servers, this can lead to Remote Code Execution (RCE), which is the ability to execute arbitrary commands on a target machine.Recommendations
Update to a version later than 0.26.7.
Exploit
Fix
RCE
Missing Authorization
Improper Privilege Management
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dokploy